Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Updated and Ongoing Supply Chain Attack Targets CrowdStrike ...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
884
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent supply chain attack dubbed the "Shai-Hulud" has compromised multiple CrowdStrike npm packages, impacting nearly 500 packages in total. The malware involved resembles previous malicious campaigns and includes a `bundle.js` script that executes secret scanning, steals tokens and cloud credentials, and creates unauthorized GitHub Actions workflows to exfiltrate sensitive data to a hardcoded endpoint. The attack exploits compromised packages to self-propagate by modifying and republishing them, injecting malicious code that executes upon installation. This operation is facilitated by using stolen credentials to target additional repositories and packages, ultimately causing widespread potential exposure. The npm registry swiftly removed affected packages, and the community is advised to uninstall or pin packages to known-good versions, audit environments for unauthorized activity, and rotate exposed credentials.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.